SecuryBlack LogoSecuryBlack
Free tool

Hardening script generator

Pick your options and download a commented bash script, ready to review and run on your Debian or Ubuntu VPS.

Don't close your current SSH session

Before closing this terminal, open a second one and confirm you can connect with the new configuration. A mistake in the firewall or SSH setup can lock you out of your own server.

Generated script

#!/usr/bin/env bash set -euo pipefail # Generated by the SecuryBlack VPS hardening generator. # Review every line before running it. Written for Debian/Ubuntu (apt + ufw) — # other distros are not supported yet. # # IMPORTANT: keep this SSH session open. Open a SECOND terminal and confirm # you can log in before closing this one — a mistake in the SSH or firewall # config below can lock you out of your own server. echo "1/4 Allowing SSH before enabling the firewall..." sudo ufw allow 22/tcp sudo ufw allow 80/tcp sudo ufw allow 443/tcp echo "Enabling UFW..." sudo ufw --force enable echo "2/4 Installing fail2ban..." sudo apt-get update sudo apt-get install -y fail2ban sudo systemctl enable --now fail2ban echo "3/4 Hardening sshd_config..." sudo sed -i 's/^#\?PermitRootLogin.*/PermitRootLogin prohibit-password/' /etc/ssh/sshd_config sudo sed -i 's/^#\?PasswordAuthentication.*/PasswordAuthentication no/' /etc/ssh/sshd_config sudo systemctl restart sshd echo "4/4 Enabling unattended security upgrades..." sudo apt-get install -y unattended-upgrades sudo dpkg-reconfigure -f noninteractive unattended-upgrades echo "Done. Do NOT close this session — open a new terminal and confirm you can log in before disconnecting."

This is the manual version of what FerroSentry does on its own

FerroSentry applies this same hardening in under a minute when you connect your server, and keeps watching afterward — if something changes, it tells you.